Vulnerabilities > Intel > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-10-15 CVE-2018-12154 Infinite Loop vulnerability in Intel Graphics Driver
Denial of Service in Unified Shader Compiler in Intel Graphics Drivers before 10.18.x.5056 (aka 15.33.x.5056), 10.18.x.5057 (aka 15.36.x.5057) and 20.19.x.5058 (aka 15.40.x.5058) may allow an unprivileged user to potentially create an infinite loop and crash an application via local access.
local
low complexity
intel CWE-835
5.5
2018-10-10 CVE-2018-12193 Unspecified vulnerability in Intel Quickassist Technology 1.0.4000004/1.7.L.4.10.0
Insufficient access control in driver stack for Intel QuickAssist Technology for Linux before version 4.2 may allow an unprivileged user to potentially disclose information via local access.
local
low complexity
intel
5.5
2018-10-10 CVE-2018-12172 Unspecified vulnerability in Intel products
Improper password hashing in firmware in Intel Server Board (S7200AP,S7200APR) and Intel Compute Module (HNS7200AP, HNS7200AP) may allow a privileged user to potentially disclose firmware passwords via local access.
local
low complexity
intel
5.5
2018-10-10 CVE-2018-12161 Information Exposure vulnerability in Intel Raid web Console 3.0
Insufficient session validation in the webserver component of the Intel Rapid Web Server 3 may allow an unauthenticated user to potentially disclose information via network access.
network
low complexity
intel CWE-200
6.5
2018-10-10 CVE-2018-12158 Information Exposure vulnerability in Intel Next Unit of Computing Firmware
Insufficient input validation in BIOS update utility in Intel NUC FW kits downloaded before May 24, 2018 may allow a privileged user to potentially trigger a denial of service or information disclosure via local access.
local
low complexity
intel CWE-200
6.0
2018-10-10 CVE-2018-12153 Improper Input Validation vulnerability in Intel Graphics Driver
Denial of Service in Unified Shader Compiler in Intel Graphics Drivers before 10.18.x.5056 (aka 15.33.x.5056), 10.18.x.5057 (aka 15.36.x.5057) and 20.19.x.5058 (aka 15.40.x.5058) may allow an unprivileged user from a virtual machine guest to potentially crash the host system via local access.
local
low complexity
intel CWE-20
6.5
2018-09-12 CVE-2018-3686 Code Injection vulnerability in Intel Sa-00086 Detection Tool 1.2.7.0
Code injection vulnerability in INTEL-SA-00086 Detection Tool before version 1.2.7.0 may allow a privileged user to potentially execute arbitrary code via local access.
local
low complexity
intel CWE-94
6.7
2018-09-12 CVE-2018-3659 Unspecified vulnerability in Intel products
A vulnerability in Intel PTT module in Intel CSME firmware before version 12.0.5 and Intel TXE firmware before version 4.0 may allow an unauthenticated user to potentially disclose information via physical access.
low complexity
intel
6.8
2018-09-12 CVE-2018-3658 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
Multiple memory leaks in Intel AMT in Intel CSME firmware versions before 12.0.5 may allow an unauthenticated user with Intel AMT provisioned to potentially cause a partial denial of service via network access.
network
low complexity
siemens intel CWE-772
5.3
2018-09-12 CVE-2018-3657 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Multiple buffer overflows in Intel AMT in Intel CSME firmware versions before version 12.0.5 may allow a privileged user to potentially execute arbitrary code with Intel AMT execution privilege via local access.
local
low complexity
siemens intel CWE-119
6.7